Security and supplier assurance

Security documentation for professional procurement

Vikingegaarden provides structured information about EMIKO hosting, backup, access control and data processing to support security review and supplier assessment.

A clear boundary for NIS 2 assessment

EMIKO security documentation can support the supplier section of a Partner's NIS 2 review. It is not a product certification, does not determine whether an organisation falls within the directive and does not replace the Partner's own legal, governance or risk assessment.

HOSTED ENVIRONMENT Curanet, team.blue Denmark DANISH AND EU DATACENTRES ISO/IEC 27001:2022 ISAE 3000 AND 3402 TYPE 2 BACKUP LAYERS 1 Storage snapshots EVERY 2 HOURS 2 DAYS 2 Veeam daily backup REPLICATED TO A SEPARATE LOCATION 30 DAYS 3 Acronis Cyber Protect Cloud SEPARATE PROVIDER, FRANKFURT, GEO REDUNDANT INDEPENDENT BACKUP PROTECTION. NOT AN UPTIME, RTO OR RPO COMMITMENT.

Backup frequency and retention are not an uptime, recovery-time objective or recovery-point commitment unless the signed service agreement states otherwise.

Access follows the organisation and responsibility

Administrative access is separated from operational and customer access. Users receive only the views and controls required by their role and approved scope.

EMIKO permissions can be scoped by the levels listed here.

  • Partner organisation and business
  • Operational location
  • Equipment group or individual asset
  • Service and permitted action
  • User role
  • Approved time period
  • Customer, staff or contractor relationship

Hosting and backup information

The EMIKO environment is hosted through Curanet, part of team.blue Denmark, in Danish and EU data centres. The provider documentation includes ISO/IEC 27001:2022 and applicable ISAE 3000 and ISAE 3402 Type 2 assurance information.

The applicable service documentation defines the exact scope and responsibilities for the contracted environment.

Documentation available for review

Subject to the relevant agreement and confidentiality requirements, Vikingegaarden can provide:

  • Hosting and data-centre description
  • Relevant provider assurance information
  • Backup and restore model
  • Role-based access-control description
  • Organisational and equipment scoping model
  • GDPR and data-processing documentation
  • Subprocessor information
  • Technical and organisational measures
  • Responses to agreed security questionnaires

What remains the Partner's responsibility

The EMIKO Partner remains responsible for its own scope and obligations under the directive.

  • NIS 2 scope and applicability analysis
  • Governance and risk management
  • User administration and internal access approvals
  • Supplier-management obligations
  • Incident reporting obligations
  • Retention and recovery requirements
  • Legal and regulatory review

Requirements beyond the standard service

Extended retention, immutable backup, scheduled restore testing, stronger recovery objectives, additional access controls and dedicated disaster-recovery arrangements must be defined in the service scope. They should not be assumed unless contractually agreed.

Book a demo